My search (1)
transaction PG SessionID mvlist=SessionEventNet nullstr=0|eventstats sum(SessionEventNet) as SessionNet
works great, my search (2)
transaction PG SessionID mvlist=PN nullstr=0|eventstats sum(PN) as CashIn
works great as well, my search (3)
transaction PG SessionID mvlist=SessionEventNet PN nullstr=0|eventstats sum(SessionEventNet) as SessionNet sum(PN) as CashIn
does not produce the desired results on CashIn, only on SessionEventNet
Anyone???
You should use quotes:
mvlist="SessionEventNet PN"
Here is how I solved it:
transaction PG SessionID mvlist=(t SessionEventNet PN) nullstr=0|eventstats sum(SessionEventNet) as SessionNet sum(PN) as CashIn
already tried it. The default delim=" ", can be changed to delim="," however I think I tried both ways.
The doc says mvlist
takes a comma-separated list of fields, so try this:
transaction PG SessionID mvlist=SessionEventNet,PN nullstr=0|eventstats sum(SessionEventNet) as SessionNet sum(PN) as CashIn
http://docs.splunk.com/Documentation/Splunk/6.0.2/SearchReference/Transaction
Did you try mvlist=(actionName,event_time*)* ?
Add () to the fileds.May be it works.
I am still not able to get 2 fields in the mvlist list. Here is my transaction line now:
| transaction visitID mvlist=actionName
i get a nice set of values that groups actions by visitID. However, if i change the above line to:
| transaction visitID mvlist=actionName,event_time
I get a totally different result set that doesn't look anything like the way i want it. Below is my full query:
source="/var/log/logstash/dynatraceqa*" businessTransaction="Real User Page Actions - Copy"
| transaction visitID mvlist=actionName
| table application, visitID, event_time, actionName, eventcount
| sort event_time
| addtotals row=f col=t fieldname=Total labelfield=actionName eventcount
| rename event_time as "Start Time", application as "Application", visitID as "Visit ID", actionName as "User Action". eventcount as "Action Count"
Hi @gt_dev
This question is over 2 years old. I'd suggest asking your own question instead of trying to get help on an old thread.
good idea
already tried it. The default delim=" ", can be changed to delim="," however I think I tried both ways.